top of page

Legacy Banking Costs: The Hidden Financial and Strategic Burden on Financial Institutions

Writer: Marcia Klingensmith
Marcia Klingensmith
Feb 25, 2025
8 min read

Updated: Aug 24

 

Modern banking technology connected by a glowing bridge to aging legacy banking infrastructure with rusted gears.

Updated August 2026


For years, the conversation about legacy banking technology has focused on maintenance costs: old systems are expensive, specialized skills are harder to find, and banks spend too much keeping existing technology running.


Those issues are real. But they are no longer the most important part of the story.

The larger challenge is that financial institutions are now operating in an environment that expects money, data, decisions, and controls to move much faster than many of their underlying systems were designed to support.


Instant payments operate around the clock. ISO 20022 carries richer and more structured payment data. APIs connect banks to fintechs and other ecosystem partners. AI increasingly depends on timely, accessible data to generate useful insights and decisions. Customers expect information and services to be available when they need them—not according to a batch-processing schedule.


That does not automatically make an older core banking system obsolete. Many legacy systems remain extremely reliable systems of record.


The question for senior leaders is different:


Can your current architecture support the way the institution needs to operate now, and where it needs to go next, without adding unsustainable cost, complexity, risk, and manual intervention?


That is where legacy banking costs become a business issue rather than simply an IT issue.


Legacy Technology is Expensive, but Be Careful with the Numbers


There is good evidence that maintaining aging payment infrastructure consumes significant resources.


IDC Financial Insights research sponsored by Episode Six estimated that global financial institutions spent $36.7 billion on outdated payment systems in 2022 and projected that spending could reach $57.1 billion by 2028, an annual growth rate of 7.8%. The same research estimated that institutions moving to more modern payments platforms could capture additional revenue opportunities and cost efficiencies through new products, Payments-as-a-Service, orchestration, reduced downtime, and lower development costs.


Those figures are useful, but they need context. They relate specifically to payments technology, not the entirety of a bank's legacy infrastructure. They also come from vendor-sponsored research and should be treated as directional evidence rather than a universal business case for every financial institution.


A broader McKinsey analysis found that at a typical bank, “run-the-bank” priorities—including technical debt and legacy infrastructure—can consume as much as 70% of technology spending.

That distinction matters.


The problem is not simply that banks spend money maintaining old systems. Every financial institution must spend money maintaining production infrastructure.


The strategic question is how much technology capacity is being consumed just to preserve the status quo, and what that prevents the institution from doing next.


The More Important Legacy Banking Cost Is the Cost of Change


This is where modernization economics become more interesting.


Legacy environments frequently include layers of customization, point-to-point integrations, duplicated data, batch processes, specialized middleware, and applications added over many years. Each individual decision may have made sense when it was made. Collectively, however, they can make seemingly straightforward changes difficult.


McKinsey has identified complex customization, extensive interfaces, technical debt, and shrinking pools of specialized expertise as recurring challenges in legacy banking environments. It also notes that modern, lightweight processors and architectures can materially shorten the time required to introduce or modify products.


A 2024 survey commissioned by 10x Banking provides another useful indicator. Among 206 senior IT decision-makers at financial institutions in the United States, United Kingdom, Australia, and South Africa:


  • 55% said limitations in their existing core banking solutions were the biggest roadblock to achieving their digital-transformation goals.

  • 53% of institutions using legacy cores reported difficulty scaling because of data silos and production bottlenecks.

  • Only 2% said they had no plans to deprecate legacy core technology.


Again, this is vendor-sponsored research, so the percentages should not be treated as universal. But the underlying issue will be familiar to many banking leaders.


The cost of legacy architecture often appears in places that are harder to find on a technology budget:

  • engineering time spent maintaining interfaces and workarounds;

  • manual reconciliation between systems;

  • duplicated data and transformation logic;

  • longer testing cycles because one change touches multiple applications;

  • additional controls created to compensate for system limitations;

  • slower introduction of new payment products and use cases;

  • difficulty using data consistently across fraud, operations, treasury, product, and customer channels; and

  • increased dependency on people who understand how years of customization actually work.

These are not simply maintenance costs. They are the cost of complexity.


Instant Payments Raise the Operating Requirement


The growth of instant payments makes this problem more visible.


In the United States, the Federal Reserve reported more than 1,500 financial institutions participating in the FedNow® Service by late 2025. FedNow processed nearly 5 million settled payments in the second quarter of 2026, an 83% increase from the prior quarter. The RTP® network processed more than 321 million payments through July 2026, averaging more than 1.5 million transactions per day.


Globally, the direction is similar. ACI Worldwide and GlobalData reported 266.2 billion instant payment transactions in 2023 and projected 575.1 billion by 2028.


But supporting instant payments is not simply a matter of connecting to another rail.

Once money can move and settle in seconds, 24/7/365, the institution also has to consider whether the processes surrounding that payment can operate at the same speed.


That includes:

  • authentication and identity;

  • fraud and scam controls;

  • sanctions and other compliance processes;

  • account and transaction limits;

  • liquidity and settlement management;

  • exception handling;

  • reconciliation;

  • customer servicing;

  • notifications;

  • data availability; and

  • operational escalation.


A bank can absolutely enable instant payments while retaining an existing core. Many do.

The challenge arises when the institution connects an always-on payment capability to operational processes that still depend heavily on batch windows, manual intervention, fragmented data, or controls designed for a very different environment.


That is why payments modernization is increasingly an architecture and operating-model issue, not merely a rail-connectivity project.


ISO 20022 Makes the Data Problem Harder to Ignore


The same shift is happening with payments data.


In November 2025, the financial community completed the transition to ISO 20022 as the standard language for cross-border payment instructions on Swift. The standard provides richer, structured payment information that can improve automation, interoperability, compliance, reconciliation, and customer insights.


But receiving richer data does not automatically create value.


If an institution must truncate that information, translate it repeatedly, place it into free-text fields, or move it through applications that cannot consume the additional structure, much of the benefit disappears.


This creates an important distinction for senior leaders:


ISO 20022 compliance is not the same thing as ISO 20022 capability.


An institution may technically process the message while still being unable to use the data consistently across fraud, reconciliation, servicing, analytics, liquidity, or customer-facing applications.


That is another form of legacy cost: the institution has access to better information but cannot fully use it.


AI Raises a Similar Question


AI creates another reason to look beyond the age of individual systems.


Banks increasingly want AI to support fraud detection, reconciliation, servicing, operational decisioning, product development, and other functions. But AI is only as useful as the data, controls, permissions, and processes surrounding it.


Fragmented data makes that harder. So does inconsistent identity management, unclear data lineage, and multiple systems producing different versions of the same information.


At the same time, modernizing technology does not automatically reduce risk. New architectures create their own security and governance requirements.


IBM's 2026 Cost of a Data Breach research found that the average financial-services breach cost $6.3 million, while AI-enabled malicious attacks increased sharply across the organizations studied. The lesson is not that legacy technology causes breaches. It is that banks are modernizing in an environment where the threat model is changing at the same time.

Modernization therefore has to improve control as well as speed.


Modernization Does Not Have to Mean Replacing the Core


This may be the most important point for senior leaders.


The choice is not:

Keep the legacy core forever or Replace everything.


Full core replacement can be expensive, disruptive, and risky. McKinsey has noted that large core transformations can run well above $100 million for mid-sized institutions and that migration risk is one reason many banks choose progressive modernization instead.


There are several ways to modernize an institution without beginning with a wholesale core replacement.


Depending on the problem being solved, the strategy may include:

  • exposing existing capabilities through modern APIs;

  • externalizing product, pricing, payment, or workflow logic from the core;

  • introducing event-driven data architecture;

  • creating a modern payment hub or orchestration layer;

  • moving selected workloads to cloud infrastructure;

  • replacing individual components where the business case is strongest;

  • launching new capabilities on a parallel modern stack; or

  • progressively reducing the role of the legacy core until it primarily performs the functions it still performs well.


McKinsey describes similar approaches as progressively “hollowing out” or decomposing the core and, in some cases, introducing a real-time data hub and routing layer around existing systems.

The point is not to modernize everything.


The point is to identify where existing architecture prevents the institution from delivering the business capability, control environment, economics, or customer experience it needs—and modernize there deliberately.


What Senior Leaders Should Be Asking


A useful modernization discussion starts with business and operational questions rather than a technology shopping list.


Senior leaders should be asking:


  • Where does our current architecture materially slow our ability to change?

  • Which processes still depend on batch cycles when the business now operates continuously?

  • Where are employees compensating for system limitations through spreadsheets, manual reconciliation, duplicate entry, or workarounds?

  • Where does valuable ISO 20022 or transaction data lose structure as it passes through our environment?

  • Which controls were designed for slower money movement and need to be reconsidered for instant payments?

  • How much of our technology capacity is spent maintaining interfaces, customizations, and technical debt rather than creating new capabilities?

  • Which capabilities genuinely belong in the core, and which could be externalized or orchestrated more effectively?

  • Can fraud, liquidity, operations, servicing, and exception management support the same operating model as the payment capability we are introducing?

  • What modernization investments reduce several constraints at once rather than solving another isolated problem?


Those questions lead to a much more useful modernization roadmap than simply asking when the institution should replace its core.


The Real Cost of Legacy Banking Technology


Legacy technology is not expensive simply because it is old.


A system that is stable, economical, well controlled, and capable of supporting the institution's strategy may continue to provide considerable value.


The cost appears when the surrounding architecture makes every new requirement harder: another integration, another translation, another reconciliation process, another manual control, another delay, or another source of operational uncertainty.


That matters more now because the environment around the core has changed.


Payments can move instantly. Data is richer. AI can produce decisions and insights faster.


Customers and businesses increasingly expect continuous access. Fraudsters adapt quickly. New rails and forms of value are expanding the choices institutions need to govern.


Financial institutions do not need to modernize everything at once.


They do need to understand where their existing architecture is constraining change, increasing risk, or consuming resources that could otherwise create value—and then sequence modernization accordingly.


For senior leaders, that is the real legacy banking cost worth measuring.


Sources & Further Reading

  • IDC Financial Insights / Episode Six — Future Ready Payments Platforms: Enabling the Next Phase of Growth for BanksIDC-sponsored research underlying the $36.7 billion legacy payments spending estimate and $57.1 billion 2028 projection.View the IDC Financial Insights InfoBrief

  • McKinsey & Company — Unlocking the Banking Technology WorkforceResearch on bank technology spending, technical debt, legacy infrastructure, technology capacity, and value generation.Read the McKinsey analysis

  • McKinsey & Company — Unlocking the Value of Technology in BankingMore recent analysis of run-the-bank and mandatory-change spending and the limited discretionary technology capacity available at many banks.Read the McKinsey analysis

  • 10x Banking — Core Banking Without Compromise2024 research commissioned by 10x Banking and conducted among 206 senior IT decision-makers at Tier I and Tier II financial institutions across four markets.View the 10x Banking research

  • Federal Reserve Financial Services — FedNow Service Volume and Value StatisticsPrimary operating statistics for FedNow volume and value.View FedNow statistics

  • The Clearing House — RTP Network Volume and Value StatisticsPrimary operating statistics for RTP network transaction volume and value.View RTP network statistics

  • Swift — ISO 20022: A New Era for Global PaymentsSwift's November 2025 update on the end of coexistence and the role of richer structured data in cross-border payments.Read the Swift update

  • McKinsey & Company — How Banks Can Use Seven Levers to Modernize Their Core SystemsDiscussion of core decomposition, APIs, microservices, data architecture, and progressive modernization strategies.Read the McKinsey modernization analysis

  • McKinsey & Company — Modernizing Core Technology, Without Breaking the BankAnalysis of progressive modernization, greenfield strategies, and alternatives to wholesale core replacement.Read the McKinsey core modernization analysis

  • IBM — Cost of a Data Breach Report 2026Current research on breach costs, financial-services exposure, AI-enabled attacks, and security AI and automation.View IBM's 2026 report

  •  

Comments


©2026 FinTech Consulting, LLC - Proprietary Framework. Use by license only.

bottom of page